Live data from Hacker News

Final thoughts on Ubiquiti

krebsonsecurity.com

111–120 of 238 posts

Re: Final thoughts on Ubiquiti

#111
If there's one thing I really hope people take away from this entire story is not to use security researchers' statements in constant appeals to authority. I hear so many questionable-to-bad takes on cyber security that basically amount to Bruce Schneier, Brian Krebs, or Troy Hunt said so, so you're absolutely wrong if you don't obey them.

It's really important to remember security researchers and experts convey what they feel is the most accurate or best advice or information they have at the time, and it may very well turn out to be completely wrong or misguided later. The fact that these individuals are popular does not mean they are an authority on anything.

Re: Final thoughts on Ubiquiti

#112

Earlier quoted context omitted.

>> 2) There was no large scale data breach Says who? The FBI? Says Ubiquiti? I bet BOTH of those places have a reason to say that, and it is green and smells of dead presidents.

Get caught in a lie in front of a jury for a white-collar criminal prosecution with any sort of competent lawyer, and you never regain credibility. Regardless, the other points still stand. It's incredibly hard to defend yourself if your head of security decides to extort you. They are the ones that design the protections to keep insider attacks from working. Luckily for Ubiquiti - the attacker screwed up his network…

>> Get caught in a lie in front of a jury for a white-collar criminal prosecution with any sort of competent lawyer, and you never regain credibility.

Which is great for mega corporations who are always innocent of any robber-baroning or impulse to make security a secondary consideration to profit.

>>Regardless, the other points still stand.

On feeble legs.

>>It's incredibly hard to defend yourself if your head of security decides to extort you. They are the ones that design the protections to keep insider attacks from working. Luckily for Ubiquiti - the attacker screwed up his network configuration (VPN leak failure) which is also somewhat ironic.

I tend to think if you have that problem, you are probably hiring people that are much like your company. To put it differently, a known liar telling a story doesn't automatically make it a lie. I suspect we will soon be seeing later how much Ubiquiti cares about its customer base. When that time happens, I will return to this post and ask you some follow up questions.

Re: Final thoughts on Ubiquiti

#113

Earlier quoted context omitted.

This is about of straightforward as a "I screwed up, I own it, I apologize" Everyone makes mistakes. Some of the good work Krebs has done seems to be completely overshadowed by a mistake here. Granted, this is probably in response to some legal action either in progress or already settled, but what more do you want from the guy?

>but what more do you want from the guy? By the time the December story was published, it seems that Krebs knew full well that his source was the person implicated in the crime to begin with. I would like to understand why he thought it was responsible to press forward while obfuscating this fact, and how he will handle similar situations moving forward. His thought process there will help inform me as to whether or…

> it seems that Krebs knew full well that his source was the person implicated in the crime to begin with

I would say implicated in a crime. It wasn't entirely clear at the time that the crime was extortion. After all, its a very odd way to make money, as going public as a "loose cannon who fucked a company by being so toxically bad at their job they brought down a company" is not the greatest CV experience post.

I'm still not entirely clear how much of the architecture described was bullshit.

Re: Final thoughts on Ubiquiti

#114
post #13
post #6

An accurate but pretty lacklustre "mea culpa" and retraction. I don't mind people making mistakes, everyone does, but seeing how Krebs has handled this whole episode has not inspired optimism in how he'll handle future mistakes. He was essentially used as an unwitting party in a cyber blackmail scheme, and he doesn't touch on that at all. There will continue to be nefarious parties trying to misuse his reputation, so…

For a site that generally is there to give you the inside scoop on what is really going on / happened, interesting / disappointing that the choice is to not do so here. To me "sorry I was wrong" isn't enough.

That's a non-answer. What more do you want? What would be "enough"?

Re: Final thoughts on Ubiquiti

#115
post #3

this reads like he got out-lawyered here. context for the unaware: https://arstechnica.com/tech-policy/2022/03/ubiquiti-sues-jo...

Do I understand this correctly? There was a minor data breach at Ubiquiti. An employee named Sharp was using this as an opportunity to extort his employer and exfiltrate data. Sharp was telling Krebs some yarn about the data breach being bigger than reported, which Krebs then repeated on his blog, accusing Ubiquiti of covering up a more significant breach. And Ubiquiti is claiming that Krebs knew the truth all along.…

That's pretty much it, yes:

https://www.justice.gov/usao-sdny/pr/former-employee-technol...

https://www.cyber.nj.gov/public-data-breaches/ubiquiti

Re: Final thoughts on Ubiquiti

#116
post #6

An accurate but pretty lacklustre "mea culpa" and retraction. I don't mind people making mistakes, everyone does, but seeing how Krebs has handled this whole episode has not inspired optimism in how he'll handle future mistakes. He was essentially used as an unwitting party in a cyber blackmail scheme, and he doesn't touch on that at all. There will continue to be nefarious parties trying to misuse his reputation, so…

This is why he should have never apologized in the first place, but rather just admit being wrong an move on. Apologies are never enough for some people, and often even weaponized.

Yep. Apologies are blood to lynch mobs.

Re: Final thoughts on Ubiquiti

#117
post #89
post #33

Earlier quoted context omitted.

The problem from my end though is, who really competes with them? No one else offers the same level of control at the same (or even close) price point.

Nobody competes with them as 'Apple for networking', but MikroTik is if anything a bit cheaper and better on the actual specs etc. - just without the snazzy UI and easy GUI (highly-G) config. There's probably a lot of people who'd love Ubiquiti gear ('gadget nerds', Linus Tech Tips viewers, gamers, etc.) to whom I wouldn't recommend MikroTik, but to anyone who's.. idk, heard of iptables, I would. All the gamer-market…

> Nobody competes with them as 'Apple for networking'

Apple used to ;_; I was still using my Airport Expresses until they gave out. Didn't care if they didn't have the latest wifi standards, they were way easier to manage than Ubiquiti or anything else.

Re: Final thoughts on Ubiquiti

#118
post #27

Earlier quoted context omitted.

This is about of straightforward as a "I screwed up, I own it, I apologize" Everyone makes mistakes. Some of the good work Krebs has done seems to be completely overshadowed by a mistake here. Granted, this is probably in response to some legal action either in progress or already settled, but what more do you want from the guy?

>Everyone makes mistakes. Fully agree, which is why I said the same thing. :) >Granted, this is probably in response to some legal action either in progress or already settled, but what more do you want from the guy? As I said in my post, a stated awareness that he was used in a cyber blackmail scheme, and at least some nominal promise to try and be aware of that in the future. The difference here is between "I made…

In the counterfactual world where he says that, the top comment on HN would have been that he's trying to weasel out of personal responsibility. Besides, let's be honest: he's going to be heavily policed by the Internet on any statement that is similar to the ones on Ubiquiti. I think he will be quite aware.

In fact, here's an example of exactly what you're saying being considered a convenient excuse: https://news.ycombinator.com/item?id=32664689

Re: Final thoughts on Ubiquiti

#119
post #27

Earlier quoted context omitted.

This is about of straightforward as a "I screwed up, I own it, I apologize" Everyone makes mistakes. Some of the good work Krebs has done seems to be completely overshadowed by a mistake here. Granted, this is probably in response to some legal action either in progress or already settled, but what more do you want from the guy?

>Everyone makes mistakes. Fully agree, which is why I said the same thing. :) >Granted, this is probably in response to some legal action either in progress or already settled, but what more do you want from the guy? As I said in my post, a stated awareness that he was used in a cyber blackmail scheme, and at least some nominal promise to try and be aware of that in the future. The difference here is between "I made…

As part of a post mortem you should ask "People will remain fallible; How can we change the process so this is unlikely to happen in the future?" And in general one likes to see that kind of transparency ... but if the the problem is someone snuck through our defenses, often we don't want want to publicize the changes made because it might help the next person.

Although a "Steps will be taken." might be nice.

Re: Final thoughts on Ubiquiti

#120
post #6

An accurate but pretty lacklustre "mea culpa" and retraction. I don't mind people making mistakes, everyone does, but seeing how Krebs has handled this whole episode has not inspired optimism in how he'll handle future mistakes. He was essentially used as an unwitting party in a cyber blackmail scheme, and he doesn't touch on that at all. There will continue to be nefarious parties trying to misuse his reputation, so…

As a third party unaffected by the events in any direct way, I don't feel it's appropriate to give an opinion on whether the apology is satisfactory or not. If Ubiquiti has one, I suppose that's for them to express, or not, as they choose.
Post reply on HN